The Change Architect logoThe Change ArchitectHumanitarian Governance

Public lesson preview

AI, data protection, and digital security for NGOs.

Follow the complete seven-lesson pathway from governance and information mapping to tested incident recovery. Every lesson combines a decision check with a practical contribution to the final Digital Resilience Pack.

Humanitarian professionals reviewing digital information and organizational safeguards
A resilient organization knows what it holds, why it holds it, who can reach it, and what must happen when a safeguard fails.
Orientation

Govern digital resilience as an operating capability

Establish the leadership decisions, accountability, and humanitarian consequences that frame the whole pathway.

  • Connect governance, protection, detection, response, and recovery.
  • Set decision rights and escalation routes.
  • Start the Digital Resilience Pack.
Lesson 1

Map sensitive information and critical operations

Build an asset and processing picture that links purpose, people, information flows, systems, dependencies, possible harm, controls, and owners.

  • Classify records by realistic consequence.
  • Trace transfers and hidden dependencies.
  • Prioritize what the organization must protect and restore.
Lesson 2

Select tools and vendors with evidence

Turn tool enthusiasm into a controlled decision about lawful purpose, access, retention, deletion, support, export, and incident readiness.

  • Define the intended use before comparison.
  • Investigate vendor and configuration gaps.
  • Record approve, restrict, pilot, or reject decisions.
Lesson 3

Control identity, access, devices, and sharing

Design daily safeguards that survive staff changes, partner work, remote access, shared links, lost devices, and urgent field operations.

  • Apply named accounts, least privilege, and MFA.
  • Review privileged access and external sharing.
  • Make onboarding and offboarding testable.
Lesson 4

Minimize, de-identify, retain, and delete safely

Reduce exposure before information enters an AI or digital workflow and keep the full lifecycle under accountable control.

  • Separate anonymization from simple name removal.
  • Test contextual re-identification risk.
  • Set retention, review, deletion, and exception evidence.
Lesson 5

Detect, contain, communicate, and recover

Build a calm incident route for accidental uploads, wrong recipients, leaked links, compromised accounts, lost devices, or harmful outputs.

  • Protect people while preserving evidence.
  • Assess notification and communication needs.
  • Restore trusted operations and learn from the event.
Lesson 6

Complete and test the Digital Resilience Pack

Bring the registers, decisions, safeguards, incident route, recovery priorities, and improvement plan into one reviewable operating package.

  • Run a tabletop exercise.
  • Record gaps, owners, deadlines, and retest points.
  • Distinguish demonstrated capability from certification.

Teaching boundary

The course teaches safer practice, not legal certification.

This preview is for professional development. It does not replace legal advice, a GDPR compliance audit, safeguarding review, donor assurance, penetration testing, or a formal information-security certification.